HOMEPLATFORMPARTNERSPRICINGRESEARCH
Who we serve
Community BanksSponsor BanksFintechs
Blog · Sponsor Banks & BaaS

Sponsor Bank Due Diligence Checklist for Fintechs

A sponsor bank due diligence checklist for onboarding fintech partners: CMS maturity, BSA/AML capability, consumer compliance, and evidence examiners expect.

By Canarie Team · April 30, 2026

The quality of due diligence a sponsor bank performs before signing a fintech partner determines the findings it will face two years later. Once a program launches under your charter, the bank owns every compliance obligation that attaches to it, so the time to discover a partner's weak complaint handling or thin BSA staffing is before the contract is signed, not during your first joint examination. This checklist covers the eight domains a bank's team should work through, and what to do with the answers.

Key Takeaways:

  • OCC Bulletin 2021-40 sets specific due diligence expectations for banks evaluating fintech companies, including how to adapt when a fintech has a limited operating history
  • Diligence should cover eight domains: corporate and financial condition, compliance program maturity, BSA/AML capability, consumer compliance, information security, operational resilience, fourth-party dependencies, and track record
  • The diligence file is itself examination evidence — examiners will ask what you reviewed, what you found, and who approved the decision
  • Findings should convert into onboarding conditions, contract terms, and monitoring requirements, not sit in a memo

What Regulators Expect Before a Fintech Relationship Goes Live

OCC Bulletin 2021-40 exists because banks kept asking how to perform due diligence on fintechs that are venture-backed, pre-profit, and short on operating history. Its answer was not to skip it. The bulletin works through six diligence areas — business experience and qualifications, financial condition, legal and regulatory compliance, risk management and controls, information security, and operational resilience — and explains how to adapt each one when the fintech cannot produce three years of audited financials.

The Interagency Guidance on Third-Party Relationships, adopted by the FDIC through FIL-29-2023, places due diligence inside a full relationship lifecycle: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. Diligence is stage two of five, and everything you learn there should shape the three stages that follow.

One framing matters before the checklist. For a sponsor bank, a fintech partner is not a vendor. A vendor sells the bank software; a partner conducts regulated activity under the bank's charter. Scope the diligence as if you were acquiring a business line, because functionally you are.


The Sponsor Bank Due Diligence Checklist, Domain by Domain

1. Corporate and Financial Condition

Confirm who you are actually partnering with. Verify the legal entity structure, capitalization table and beneficial ownership, funding history and investor commitments, monthly burn rate and runway, and financial statements — audited where they exist, management-prepared and scrutinized where they don't. A fintech with nine months of runway is a wind-down risk the bank underwrites on day one.

2. Compliance Program Maturity

Demand evidence that a compliance management system exists before launch, not a promise to build one afterward. At minimum: written compliance policies approved by the fintech's leadership, a named compliance officer with real authority, a training program, a monitoring and testing plan, and a documented complaint-handling process. Since the partner will be inheriting your bank's standard anyway, the practical question is how far the fintech's program sits from that standard today.

3. BSA/AML Capability

Review the fintech's CIP procedures against your bank's own standards, its sanctions and watchlist screening (vendor, list coverage, match thresholds), its transaction monitoring approach and alert-handling staffing, and the experience of whoever runs its BSA function. The legal baseline is fixed: 31 CFR § 1020.210 puts the BSA program obligation on the bank, so the question is not whether the fintech's program is adequate in the abstract — it is whether the fintech can execute your program.

4. Consumer Compliance

Examine template disclosures for the products planned (Reg Z, Reg E, Reg DD as applicable), the marketing review and approval workflow, complaint intake and escalation procedures, and any prior regulatory or litigation history involving consumer protection. Ask to see the last ten complaints and how each was resolved. The responses reveal more than the policy does.

5. Information Security and Data Handling

The GLBA Safeguards Rule (16 CFR Part 314) applies to customer data the moment the program launches. Review penetration test results, SOC 2 reports — including the exceptions inside them, not just the cover page — access controls, encryption standards, incident response plans, and data flow diagrams showing exactly where bank customer data will live.

6. Operational Resilience and Business Continuity

Evaluate uptime history, disaster recovery and business continuity plans along with actual test results, prior incident history, and key-person risk in engineering and operations. A fintech that has never run a failover test has a plan on paper, not a capability.

7. Fourth-Party Dependencies

Map every material provider the fintech depends on: middleware or BaaS platform, KYC and fraud vendors, card processors, cloud infrastructure, ledger providers. The interagency guidance expects the bank to understand these dependencies because a fourth party's failure lands on the bank all the same. Request the fintech's own vendor inventory and its diligence file on each critical provider.

8. References and Track Record

Speak with prior or current bank partners where they exist, and ask pointed questions: Did evidence arrive on time? How did the fintech respond to findings? Why did any prior relationship end? Check founder backgrounds and prior regulatory history. A short track record is not disqualifying under OCC 2021-40, but it shifts weight onto the other seven domains and justifies tighter launch conditions.


Board Approval and Risk-Rating the New Partner

Diligence should end with two governance artifacts. The first is a risk rating for the partner — driven by product risk, target customer base, projected volumes, and the diligence results — which then sets the oversight cadence: how often the bank reviews the partner, how deep those reviews go, and what evidence flows monthly versus quarterly.

The second is board or designated committee approval supported by a written risk assessment. Examiners will read the approval minutes to confirm directors saw the diligence results, including the adverse ones, before voting. A rubber-stamp approval creates its own finding: the record should show what the board was told about the gaps, not only the strengths.


Turn Diligence Findings Into Conditions, Not a Memo

The most common diligence failure is not missing a red flag. It is finding one, noting it, and launching anyway with nothing changed. Every material gap should convert into one of three things:

  • An onboarding condition — the gap closes before launch (a compliance officer hired, complaint procedures documented and tested)
  • A contractual requirement — the obligation is written into the agreement with a deadline and consequences for missing it
  • A monitoring requirement — the risk is accepted and assigned a specific scheduled check, such as a monthly complaint file review or an early partner compliance review at 90 days instead of the standard annual cycle

This is also what examiners look for. OCC Bulletin 2021-40 is explicit that diligence should inform how the bank manages the relationship going forward, which means the diligence file, the contract, and the monitoring plan should visibly connect. A diligence memo that no downstream artifact references is evidence the bank performed a ritual, not a control.


How Sponsor Banks Carry Diligence Into Day-One Oversight

The handoff between diligence and oversight is where findings get lost. The team that evaluated the fintech moves on, the contract gets signed, and the monitoring plan gets rebuilt from scratch — often missing half of what diligence flagged.

Canarie closes that gap structurally. The bank defines its partner requirements once — the diligence domains, the CMS elements, the evidence standards — and every prospective partner is evaluated against the same standard, so comparisons across the portfolio are direct rather than anecdotal. When a partner signs, diligence findings convert straight into that partner's obligations: conditions become tasks with owners and deadlines, accepted risks become scheduled monitoring with defined evidence, and the partner's full compliance program is provisioned on day one instead of assembled over the first year.

See how sponsor banks run one standard across every partner →


Frequently Asked Questions

How long does sponsor bank due diligence on a fintech partner take?

For a bank with a defined diligence standard, expect eight to sixteen weeks depending on the product's risk profile and how quickly the fintech produces documents. Banks running their first fintech diligence typically take longer because they are building the checklist and the evaluation criteria at the same time. The timeline compresses significantly when the bank's requirements are published up front, since the fintech can assemble its diligence package against a known standard rather than responding to requests one at a time.

What if a fintech is too early-stage to produce audited financials?

OCC Bulletin 2021-40 addresses this directly: banks may rely on alternative information, such as interim financial statements, funding commitments from investors, and projections tested against the fintech's actual burn rate. The absence of audited financials raises the weight on other domains — management background, investor quality, and compliance program maturity — and typically justifies compensating controls like more frequent financial reporting after launch. What the bulletin does not permit is treating a short track record as a reason to skip the analysis.

Should due diligence be repeated after onboarding?

Yes. The interagency guidance treats diligence as the entry point to ongoing monitoring, not a one-time gate, and examiners expect periodic refreshes of the same domains: financial condition, compliance performance, security posture, and fourth-party dependencies. Most sponsor banks refresh the full file annually and re-diligence specific domains sooner when triggers fire, such as a leadership change, a funding event, a material vendor swap, or a spike in complaints.

Who at the bank should own fintech partner due diligence?

Ownership should sit with a named function — typically the third-party risk or fintech program office — with mandatory input from compliance, BSA, information security, and credit where relevant. What examiners look for is a documented process with defined reviewers and an approval chain that ends at the board or a board-designated committee. Diligence performed informally by whoever has spare capacity produces inconsistent files, and inconsistent files are exactly what examination teams flag when they compare partners side by side.

Topics:Sponsor BanksBaaSThird-Party RiskDue Diligence

Ready to automate your compliance workflows?

See how Canarie transforms regulatory requirements into executed tasks with built-in evidence capture.

Explore the platform